HP MSR2000/3000/4000 Router Series Security Configuration Guide
20
To configure user group attributes:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Create a user group and
enter its view.
user-group group-name
By default, there is a
system-defined user group named
system, which is the default user
group.
3. Configure authorization
attributes for the user group.
authorization-attribute { acl
acl-number | callback-number
callback-number | idle-cut minute |
vlan vlan-id | work-directory
directory-name } *
By default, no authorization
attribute is configured for a user
group.
4. (Optional.) Configure
password control attributes
for the user group.
• Set the password aging time:
password-control aging
aging-time
• Set the minimum password length:
password-control length length
• Configure the password
composition policy:
password-control composition
type-number type-number
[ type-length type-length ]
• Configure the password
complexity checking policy:
password-control complexity
{ same-character | user-name }
check
• Configure the maximum login
attempts and the action to take for
login failures:
password-control login-attempt
login-times [ exceed { lock |
lock-time time | unlock } ]
Optional.
By default, the user group uses
the global password control
settings. For more information,
see "Configuring password
control."
Displaying and maintaining local users and local user groups
Execute display commands in any view.
Task Command
Display the local user
configuration and online user
statistics.
display local-user [ class { manage | network } | idle-cut { disable | enable }
| service-type { ftp | lan-access | portal | ppp | ssh | telnet | terminal } |
state { active | block } | user-name user-name | vlan vlan-id ]
Display the user group
configuration.
display user-group [ group-name ]










